SVC—04 · EXERCISE
Red team and adversary emulation
A time-boxed, threat-informed exercise with deconfliction, stop conditions, and evidence of executed, prevented, and detected behaviors.
Start scopingTEST BOUNDARY
What sits inside the boundary
ACCESS MODES
Knowledge level is scoped
DELIVERY—LEDGER
Deliverables you can inspect.
Objective and attack-chain narrative
Executed, detected, and prevented behavior record
Purple-team debrief and control improvements
Objectives, duration and team composition
Permitted techniques and initial-access assumptions
Geography, on-site work and deconfliction
ATT&CK mapping is not a promise of complete coverage
Social, physical, and persistence actions require explicit scenario authorization
POINT—IN—TIME
Precision includes what we do not claim.
A penetration test provides evidence about named assets, versions, access, and time. It does not guarantee the absence of vulnerabilities, replace internal vulnerability management, or constitute compliance certification.
Method and limitations